Privacy

Information on the processing of personal data

Pursuant to Articles 13–14 of Regulation (EU) 2016/679 (GDPR) — Last updated: April 2026

1. Data controller

The controller of your personal data is Rayo Consulting, reachable by email at info@rayo.consulting.

Under Article 13 GDPR, the controller must provide this information before or at the time personal data is collected. You may contact us at any time to exercise your rights or to ask any question about how your data is processed.

2. Personal data collected

Through the booking form we collect the following categories of personal data:

Identity and contact data

Required to manage the booking

First and last name

Work email address

Professional data

Required to qualify the request

Company you work for and professional role

Company size (bracket, e.g. 1–10 employees)

Indicative project budget

How urgent the need is

How you heard about Rayo Consulting

Project data

Required to qualify the request

Description of the use case and business challenge (free text)

Company website

Optional

URL of the company website (not required)

Booking data

Generated automatically by the system

Date and time selected for the call

Unique booking identifier

Generated Google Meet link

Date and time the booking was created

We do not collect special categories of personal data under Article 9 GDPR (health, biometric, racial or ethnic origin, political opinions, etc.).

3. Purposes and legal basis of processing

Your data is processed for the following purposes:

A — Managing and confirming the booking

We use your identity data and email address to create the event in our team’s Google Calendar, generate the Google Meet link, send you the booking confirmation and handle any changes or cancellations.

Legal basis: Article 6(1)(b) GDPR — steps taken at the request of the data subject prior to entering into a contract.

B — Commercial qualification of the prospect

Information about your company, budget, use case and urgency lets us prepare for the call in a targeted way and assess whether the prospect’s needs fit the services Rayo Consulting offers, avoiding calls that would be unproductive for both parties.

Legal basis: Article 6(1)(f) GDPR — legitimate interest of the controller in pre-qualifying commercial enquiries. That legitimate interest is balanced against the interest of the lead, who provides this information voluntarily and receives more targeted advice in return.

C — Internal notification to the Rayo team

When a booking is made we send an internal email notification containing the lead’s data in order to prepare for the call. This data is not shared with third parties beyond the technical providers listed in section 5.

Legal basis: Article 6(1)(f) GDPR — the controller’s legitimate organisational interest.

Data is not used for automated profiling under Article 22 GDPR, nor to send unsolicited commercial communications.

4. How data is processed

Processing is carried out using electronic tools. Data is protected with technical and organisational measures appropriate to the risk, including:

  • Encrypted transmission over HTTPS (TLS 1.2+) between the browser and the servers
  • Access to the Firestore database exclusively through the server-side Admin SDK, with no credentials exposed to the browser
  • No OAuth token or credential is ever transmitted to the client
  • Service credentials are stored as encrypted environment variables on the production server
  • Firestore security rules deny direct access from unauthenticated clients

5. Recipients and processors

Data is disclosed exclusively to the following technical service providers, acting as data processors under Article 28 GDPR:

Google Ireland Limited

Gordon House, Barrow Street, Dublin 4, Ireland

Firebase Firestore: cloud database storing booking and lead data

Google Calendar API: creating and managing booking events in the team calendar

Google Meet: generating the video conference link tied to the booking

Google privacy policy →

Zoho Corporation B.V.

Beneluxlaan 4B, 3527 HT Utrecht, Netherlands

Zoho Mail EU (smtp.zoho.eu): EU-based SMTP server used to send booking confirmation emails to the lead and internal notifications to the Rayo team

Zoho privacy policy →

No data is sold, transferred to third parties for marketing purposes, or shared with anyone not listed in this notice.

6. International data transfers

Google Ireland Limited, as part of the Google LLC group, may transfer or process data outside the European Economic Area (EEA), in particular in the United States of America.

Such transfers take place under the safeguards set out in Chapter V of the GDPR (Articles 44–49), in particular through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • EU–US Data Privacy Framework (European Commission adequacy decision of July 2023)

Zoho Corporation B.V. processes data exclusively on servers located in the European Union (smtp.zoho.eu). No transfer outside the EEA by Zoho is envisaged for the services described here.

7. Data retention period

Personal data is retained only for as long as strictly necessary to achieve the purposes for which it was collected:

  • Booking data (date, time, Meet link) is retained for 24 months from the date of the call, unless longer retention is required for contractual or legal reasons
  • Lead data (identity, company and qualification data) is retained for 24 months from the date of the call, or for the duration of any commercial relationship
  • The Google Calendar event is retained until manually deleted by the Rayo team
  • Confirmation emails remain in the recipients’ mailboxes

You can request early deletion of your data at any time by writing to info@rayo.consulting. We will respond within 30 days.

8. Cookies and tracking technologies

This site does not use profiling cookies, third-party advertising cookies, or behavioural tracking technologies.

Only technical cookies strictly necessary for the site to work are used, including the NEXT_LOCALE cookie that remembers the language you chose. These cookies do not require consent under Article 122 of the Italian Privacy Code and the ePrivacy Directive 2002/58/EC.

9. Your rights as a data subject

Under Articles 15–22 GDPR, you have the right to:

Right of access (Art. 15) — Obtain confirmation as to whether personal data concerning you is being processed and, if so, access to that data and to information about the processing.

Right to rectification (Art. 16) — Obtain the rectification of inaccurate or incomplete personal data concerning you.

Right to erasure (“right to be forgotten”) (Art. 17) — Obtain the erasure of your personal data where it is no longer necessary for the purposes it was collected for, where you withdraw consent, or where processing is unlawful.

Right to restriction of processing (Art. 18) — Obtain restriction of processing in certain circumstances (e.g. while the accuracy of the data is verified or an objection is examined).

Right to data portability (Art. 20) — Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller, where technically feasible.

Right to object (Art. 21) — Object at any time to processing based on the controller’s legitimate interest, including profiling. The controller will stop processing your data unless it demonstrates compelling legitimate grounds.

Right not to be subject to automated decision-making (Art. 22) — Not be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Note: this system makes no automated decisions.

To exercise any of the rights listed above, write to info@rayo.consulting stating the right you intend to exercise and enough information to identify you. We will reply within 30 days of receiving the request, as required by Article 12 GDPR.

If you consider the response unsatisfactory, or if the controller fails to act, you have the right to lodge a complaint with the competent supervisory authority:

Garante per la protezione dei dati personali (Italian Data Protection Authority)

Piazza Venezia 11 – 00187 Rome (RM), Italy

Tel. +39 06 696771

www.garanteprivacy.it →

10. Updates to this notice

This notice may be updated to reflect changes to the services, to applicable law, or to processing practices. The current version is always available at this address (/privacy).

In the event of material changes affecting your rights, we will inform you by email if you have made a booking with us.

Version in force: April 2026